Invention Grant
- Patent Title: Streaming insertion of tokens into content to protect against CSRF
- Patent Title (中): 将令牌插入内容以防止CSRF
-
Application No.: US12761965Application Date: 2010-04-16
-
Publication No.: US08438649B2Publication Date: 2013-05-07
- Inventor: Jeffrey Ichnowski
- Applicant: Jeffrey Ichnowski
- Applicant Address: US CA San Mateo
- Assignee: Success Factors, Inc.
- Current Assignee: Success Factors, Inc.
- Current Assignee Address: US CA San Mateo
- Agency: Patterson & Sheridan LLP
- Main IPC: H04L9/00
- IPC: H04L9/00

Abstract:
Methods and apparatus are provided for protecting against cross-site request forgeries (CSRFs) by requiring certain requests submitted to a computer server to include specific tokens. The requests involve modification of or access to protected data, and the tokens are inserted by a state machine into content from which the requests are initiated. For example, content that includes a form, a hyperlink, a scripted request or other control for initiating a follow-on request to the server is modified to include tokens. The state machine may scan the content in real time (e.g., as it is served) to identify these controls and to insert the tokens. Using a state machine allows the content to be streamed even as it is scanned, does not require construction of a representation of the content (e.g., a DOM tree), and avoids modifying any of the content other than to insert one or more tokens.
Public/Granted literature
- US20110258704A1 STREAMING INSERTION OF TOKENS INTO CONTENT TO PROTECT AGAINST CSRF Public/Granted day:2011-10-20
Information query